Skip to content

Geo blocking

Geo blocking is configured per proxy host, and per L4 host. It needs MaxMind GeoLite2 databases, which CPM can keep updated for you.

Type Example What it matches
Country DE ISO 3166-1 alpha-2 country code
Continent EU AF, AN, AS, EU, NA, OC, SA
ASN 24940 Autonomous System Number
CIDR 91.98.150.0/24 An IP range
IP 91.98.150.103 One exact address

Rules are either block or allow, and allow rules take precedence. That ordering is what makes the useful shape possible: block an entire continent, then allow the two ASNs or addresses that should still get through.

Geo blocking on a proxy hostEvery country and continent is really in there.DemoNothing you change here is saved
Geo Blocking
Checking GeoIP databases
Block or allow traffic by country, continent, ASN, CIDR, or IP
Presets:
Autonomous System Numbers - press Enter to add
Press Enter to add
Press Enter to add
Used to parse X-Forwarded-For. Use private_ranges for all RFC-1918 ranges.
Blocks requests where the real client IP cannot be determined, e.g. behind a trusted proxy with no usable X-Forwarded-For. Default: off (fail-open).
HTTP status when blocked
Body text returned to blocked clients
If set, sends a 302 redirect instead of the status/body above
Custom Response Headers
No custom headers - use the + button to add one.

If the real client address cannot be determined - behind a trusted proxy that sent no usable client-IP header, say - fail-closed mode rejects the request rather than letting it past. Off by default, because the safer choice for most deployments is that a misconfigured proxy does not take the site down; on when the block list is a security control rather than a nuisance filter. It is an HTTP option: an L4 host has no headers to trust.

A blocked HTTP request gets a status code and body you choose. At layer 4 there is nothing to answer with, so the connection is closed.

If CPM sits behind another proxy, the client address it sees is that proxy’s. Settings → Network → Trusted Proxies tells Caddy which addresses to trust and which header carries the real client IP, so geo rules match the visitor rather than your load balancer. The global list can seed the global geoblock trusted-proxy list while that is empty, which hosts in merge mode inherit, so the two cannot silently disagree.

  1. Register for a free account at maxmind.com.

  2. Generate a licence key with GeoLite2-Country, GeoLite2-City and GeoLite2-ASN permissions.

  3. Open Settings → Geo-blocking → GeoIP Databases, tick Use GeoIP, and enter the account ID and key.

That is the whole setup. The controller downloads the databases, checks MaxMind for updates once a day by default, and every agent fetches them from it. With the toggle off the host forms still show the geo blocking fields, marked GeoIP off, and no country is recorded against an event.